View in browser

Weekly newsletter n°44

offsec.tools

A vast collection of security tools for bug bounty, pentest and red teaming
offsec.tools is a vast listing of security tools designed to help pentesters and bug hunters in their daily task. The list is organized by tags and provide a quick search engine. The list is feeded by the author and the community. Anyone can add a tool and be listed as a contributor, feel free to check the GitHub repository.

Go to offsec.tools

Tools featured this week

sshLooter
Script to steal passwords from ssh.
SubDomainizer
A tool to find subdomains and interesting things hidden inside.
bbot
OSINT automation for hackers.
MagicRecon
A powerful shell script to maximize the recon and data collection process.
wacker
A WPA3 dictionary cracker.
DivideAndScan
Divide full port scan results and use it for targeted Nmap runs.
LaZagne
Credentials recovery project.
AhMyth Android RAT
Android remote administration tool.
S3Scanner
Scan for open S3 buckets and dump the contents.
deser-node
NodeJS deserialization payload generator.

Tools added last week

hetty
An HTTP toolkit for security research.

ImHex
Hex editor for reverse engineers, programmers and people who value their retinas when working at 3am.

holehe
Check if the mail is used on different sites and retrieve informations on sites.

tfsec
Security scanner for your Terraform code.

sandsifter
The x86 processor fuzzer.

django-DefectDojo
DevSecOps, ASPM, Vulnerability Management.

zmap
Fast single packet network scanner designed for Internet-wide network surveys.

zgrab
Fast Go application scanner.

zdns
Fast CLI DNS lookup tool.

webhook.site
Easily test HTTP webhooks with this handy tool that displays requests instantly.

pipedream
Collect HTTP or webhook requests and inspect them in a human-friendly way.

trape
People tracker on the Internet: OSINT analysis and research tool.

The HTTP Garden
Differential testing and fuzzing of HTTP servers and proxies.

Want to see more tools?

Go to offsec.tools

Sponsors